I might be wrong but it looks like bzip2-1.0.2-11.i386.rpm will be included in SME Server Version 7.0
Quite so - perhaps. If RedHat release an update then the updated version will be included in Version 7.0.
You don't say why you mention this.
If you are aware of any security vulnerabilities, or have any security concerns, you should of course mail them to security@contribs.org.
High Charlie,
after thouroughful browsing I noticed that SME Server Version 6.0, 6.0.1, 6.5RC1, as well as the latest 7.0alpha11 isoimage have bzip2 in version 1.0.2 with different minor versions included. Reading by chance about this security warning I upgraded my bzip2 to version 1.0.3 which till now was not announced to be affected. But who knows what the future will bring ? So I mailed this the new bzip2...rpm together with that type of security annoucement to security@contribs.org as you proposed, thank you for your hint. My concern is a minor and the idea behind is to contribute to the community.
receive my kindest regards
Gerald
table which release of SME uses which version of bzip2
SME Version . . bzip2 version
6.0 . . . . . . . . . . bzip2-1.0.2-2.i386.rpm
6.0.1 . . . . . . . . bzip2-1.0.2-2.i386.rpm
6.5RC1 . . . . . . bzip2-1.0.2-2.i386.rpm
7.0alpha11 . . . bzip2-1.0.2-11.i386.rpm
PS: securityfocus till now announces that the different vendors do not supply any patch
Workaround:
Avoid processing archives in world or group writeable directories.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue.[/list]